3 ms·
I like CoreOS because of the fact that all config, etc files, sysctls are in one place. Previously, I was using artix and had this “etc” directory[1] checked i
by ebrahimh 16d ago
I like CoreOS because of the fact that all config, etc files, sysctls are in one place.
Previously, I was using artix and had this “etc” directory[1] checked in to keep track of system configuration, but there was no good way to keep track of config drift (other than remembering to update this dir).
Haven’t gone through a CoreOS update yet (been using for ~2 months), but doubtful it would break anything. I’ve tested to make sure all my containers shutdown gracefully etc.
The SOPS (secrets.yaml) pattern is more common in NixOS configs, and I found it works nicely here too. In the artix setup, I had a bunch of .example files strewn around [2], which I had to remember to sync with the real versions.
Encrypting a key is just prefixing it with “enc_priv_”, SOPS will encrypt and decrypt it automatically. I keep “public” values plaintext to maybe help someone setting this up for themselves. Just have to double-check git diff before committing.
[1] https://github.com/ebrahim37/infra-template/tree/00eccff06aed3b65287ab348fb4a725dccd51986/etc https://github.com/ebrahim37/infra-template/tree/00eccff06ae...
[2] https://github.com/ebrahim37/infra-template/blob/00eccff06aed3b65287ab348fb4a725dccd51986/rybbit/env/backend.env.example https://github.com/ebrahim37/infra-template/blob/00eccff06ae...